The small codebase has no tests or security scanning, and the repository has seen no recent activity. It is licensed, documented, and focused, but adopting this old release carries substantial maintenance risk.
38%
Total Score
25
100
75
50
This is the package's only release, published about 8 years ago, with no releases in the last 12 months. That strongly raises abandonment and compatibility risk.
The repository has had zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no updates since 2018.
One individual has registry publishing access, and the project is user-owned rather than organization-backed. This leaves limited visible maintenance capacity, especially alongside the long inactivity period.
The repository has 1 star and 1 fork, providing little evidence of broad adoption or an active community to compensate for the inactive maintainer.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest supply-chain hygiene gap rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.